<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE1-SA-2024-0059</id>
    <title>An update for open-vm-tools is now available for HCE 1.1</title>
    <severity>Important</severity>
    <release>HCE 1.1</release>
    <issued date="2024-09-27 08:26:20"/>
    <updated date="2024-09-27 08:26:20"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-34059" id="CVE-2023-34059" title="CVE-2023-34059 Base Score: 7.0 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-34058" id="CVE-2023-34058" title="CVE-2023-34058 Base Score: 7.5 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the 
/dev/uinput file descriptor allowing them to simulate user inputs. (CVE-2023-34059)

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted  Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged  Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html . (CVE-2023-34058)
</description>
    <pkglist>
      <collection short="HCE 1.1" package="open-vm-tools">
        <name>HCE 1.1</name>
        <package arch="x86_64" name="open-vm-tools" version="11.0.5" release="3.hce1c.9">
          <filename>open-vm-tools-11.0.5-3.hce1c.9.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="open-vm-tools-desktop" version="11.0.5" release="3.hce1c.9">
          <filename>open-vm-tools-desktop-11.0.5-3.hce1c.9.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
